Methods and apparatus for malware threat research
Abstract
Methods for classifying computer objects as malware and the associated apparatus are disclosed. An exemplary method includes, at a base computer, receiving data about a computer object from each of plural remote computers on which the object or similar objects are stored and or processed and counting the number of times in a given time period objects having one or more common attributes or behaviors that have been seen by the remote computers. The counted number is then compared with the expected number based on past observations, and if the comparison exceeds a predetermined threshold, the objects are flagged as unsafe or as suspicious.
Claims
exact text as granted — not AI-modified1 . A computer program product comprising a non-transitory computer-readable medium storing thereon a set of instructions executable by a processor, the set of instructions comprising instructions for:
receiving checksum data about a computer object from each of plural remote computers on which the computer object is located; storing said checksum data in a database; and presenting, on a display and in response to receiving a selection of a first group of plural objects having commonality amongst an attribute, information relating to a second group of plural objects including the first group of plural objects and additional objects not in the first group of plural objects, and information relating to one or more checksummed attributes of the objects of the second group of plural objects from the database, the information relating to the second group of plural objects being arranged such that one or more values of the one or more checksummed attributes and one or more symbols are shown, wherein the one or more symbols are assigned to the one or more values based on at least one of a uniqueness and a commonality among the one or more values of the one or more checksummed attributes of the second group of plural objects, wherein information relating to another group of plural objects comprises a number of known objects that are not malware, a number of known malware objects, and a number of unknown objects; presenting on the display, a first symbol assigned to one or more values based on the uniqueness of the one or more values among the second group of plural objects when one or more values of the one or more checksummed attributes is unique amongst the second group of plural objects; and presenting on the display, a second symbol, different from the first symbol, when one or more values of the one or more checksummed attributes is common amongst the second group of plural objects.
2 . The computer program product of claim 1 , wherein the information relating to the second group of plural objects is displayed in tabular form with rows of the table corresponding to objects and columns of the table corresponding to attributes of the objects.
3 . The computer program product of claim 1 , wherein at least one of the first and second symbols comprises a symbol having at least one of a shape and a color different than another symbol.
4 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for:
identifying commonality of one or more attribute values between the second group of plural objects; and refining a query in accordance with said identified commonality.
5 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for creating a rule from a user query if it is determined that the user query is deterministic in identifying malware.
6 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for:
monitoring user groupings of objects along with any and all user actions taken such as classifying the objects of the second group of plural objects as being safe or unsafe; and automatically applying said groupings and actions in generating new rules for classifying objects as malware.
7 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for applying the rule to an object at a first computer.
8 . The computer program product of claim 7 , wherein the set of instructions further comprises instructions for:
storing a classification of the object as safe or unsafe according to the rule in the database.
9 . The computer program product of claim 8 , wherein the set of instructions further comprises instructions for:
receiving an indication from a remote computer that an object classified as malware by said rule is believed not to be malware; and amending or deleting the rule in accordance with said indication.
10 . The computer program product of claim 5 , wherein the set of instructions further comprises instructions for sending the rule to a remote computer such that the remote computer can apply the rule to an object at the remote computer.
11 . The computer program product of claim 10 , wherein the set of instructions further comprises instructions for:
storing a classification of the object as safe or unsafe according to the rule in the database.
12 . The computer program product of claim 11 , wherein the set of instructions further comprises instructions for:
receiving an indication from the remote computer that an object classified as malware by said rule is believed not to be malware; and amending or deleting the rule in accordance with said indication.
13 . The computer program product of claim 1 , wherein the set of instructions further comprises instructions for receiving actor information pertaining to an actor object performing an act and victim information pertaining to a victim object upon which the act is being performed.
14 . The computer program product of claim 1 , wherein the one or more checksummed attributes correspond to an object pathname and an object filename.
15 . The computer program product of claim 1 , where the set of instructions further comprises instructions for displaying a third symbol, different from the first symbol and the second symbol, when one or more values of the one or more checksummed attributes is common amongst the second group of plural objects.Join the waitlist — get patent alerts
Track US2020177552A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.